Description
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.

Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution or Denial of Service via oversized Host header
Action: Patch immediately
AI Analysis

Impact

A buffer overflow occurs in Apache HTTP Server's mod_vhost_alias module when a client sends a Host header longer than 8192 bytes while VirtualDocumentRoot uses a hostname format specifier. The flaw can lead to a denial of service or, under certain conditions, arbitrary code execution. The weakness is a classic stack-based buffer overflow (CWE-121).

Affected Systems

Apache Software Foundation's Apache HTTP Server, versions through 2.4.68, on all platforms. The vulnerability is present in any configuration that uses VirtualDocumentRoot with hostname format specifiers and has LimitRequestFieldSize increased beyond the default value.

Risk and Exploitability

The vulnerability is accessible to a remote client via an HTTP request and requires only an oversized Host header. The CVSS score of 7.5 indicates a medium to high severity. While the EPSS score is not available and the issue is not listed in CISA's KEV catalog, the potential impact of arbitrary code execution or service disruption makes it a high‑risk flaw. Exploitation would involve sending a specially crafted HTTP request with a large Host header to trigger the overflow. The condition that virtual hosting and a non-default LimitRequestFieldSize are enabled is a prerequisite for exploitation.

Generated by OpenCVE AI on October 1, 2026 at 20:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Apache HTTP Server to version 2.4.69 or later.
  • Re‑evaluate the need for VirtualDocumentRoot with hostname format specifiers and disable or remove that configuration if it is not essential.
  • Reset LimitRequestFieldSize to the default of 8192 bytes or lower it to prevent oversized header requests from reaching the vulnerable code.

Generated by OpenCVE AI on October 1, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Vendors & Products Apache
Apache http Server

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Title Apache HTTP Server: mod_vhost_alias stack overflow
Weaknesses CWE-121
References

Subscriptions

Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:30.262Z

Reserved: 2026-07-16T09:06:13.760Z

Link: CVE-2026-63292

cve-icon Vulnrichment

Updated: 2026-10-01T20:09:30.262Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:29.803

Modified: 2026-10-01T21:17:23.610

Link: CVE-2026-63292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:14Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow